← All Advisories

CVE-2026-88920

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-88920

Key Details

CVECVE-2026-88920
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsApache wss4j and Apache Software Foundation Apache WSS4J
Classified asCWE-287 (Improper Authentication)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Apachewss4j
Apache Software FoundationApache WSS4J
SubsystemsGeneral OT
SectorsMultiple

What to Know

An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key.

Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. (NVD)

What to Do

Monitor Apache's and Apache Software Foundation's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-88920
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-88920
Vendor advisoryhttps://lists.apache.org/thread.html/grt43m3bgbzz0mk0cnho3rcybb1j01z9